CVE-2026-94570
CVE-2026-94570
CVSS Score
5.9
EPSS Score
0.0%
EPSS Percentile
0th
SGLang contains a DoS vulnerability caused by missing input validation for AUX_DATA ZeroMQ control messages in the Decode worker, which enables an unauthenticated remote attacker with network reachability to the Decode control PULL socket to terminate the Decode control thread and cause a denial of service against the target server.
| Vendor | sglang |
| Product | sglang |
| Published | Sep 22, 2026 |
| Last Updated | Sep 22, 2026 |
Stay Ahead of the Next One
Get instant alerts for sglang sglang
Be the first to know when new medium vulnerabilities affecting sglang sglang are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
SGLang / SGLang
0 โค 0.5.15